Is SOC 2 a certification?
No. It's an auditor's report
Who can touch production, and who approved it
The video, without the music
SOC 2 is a report, not a law or a certificate. An outside auditor checks how a company protects its customers' data. A Type 1 report covers one day, and a Type 2 covers months. When your client goes for one, the auditor looks at the app you built and asks who can reach production and who approved that access. A shared login nobody turned off after handoff becomes a finding against your client.
No. It's an auditor's report
Type 1 checks that the controls were designed right on one day. Type 2 checks that they kept working over a period, usually 3 to 12 months
Yes. Any agent or MCP server with database or deploy access is access the auditor will ask about
A report under the AICPA's Trust Services Criteria, written by an outside auditor. Bigger US customers ask for it before they sign
Your accounts, keys and deploy paths are part of what the auditor reviews when your client goes for the report
Every person, key, service account and AI agent that can reach production, what each one can read or write, and where it is defined. It also flags the risky ones: shared logins, keys in git history, leftover agency accounts and deploys without review
Who signed off on each access, and the months of proof a Type 2 report needs. That record lives outside the code
Ready to copy into Claude. It reads your code and settings and changes nothing
The findings an auditor writes up against your client
So you don't chase keys that are safe by design
What to turn off at handoff, and the record a Type 2 checks for months
The prompt to give Claude, what to look for in its answer, what you can ignore, and the proof you have to keep for the auditor



An engineer checks it, fixes it, tests it and puts their name on it